CVE Database

52322+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-10190
6.4 MEDIUM

The WP Easy Toggles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'toggles' shortcode in all versions up to, and including, …

Oct 11, 2025
CVE-2025-10175
6.5 MEDIUM

The WP Links Page plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 4.9.6 due …

Oct 11, 2025
CVE-2025-10167
6.4 MEDIUM

The Stock History & Reports Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_stock_snapshot_restocked shortcode in all versions …

Oct 11, 2025
CVE-2025-10129
6.4 MEDIUM

The WordPress Live Webcam Widget & Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'webcam' shortcode in all versions up …

Oct 11, 2025
CVE-2025-58297
5.9 MEDIUM

Buffer overflow vulnerability in the sensor service. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58295
5.9 MEDIUM

Buffer overflow vulnerability in the development framework module. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58288
5.5 MEDIUM

Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-11594
5.3 MEDIUM

A vulnerability has been found in ywxbear PHP-Bookstore-Website-Example and PHP Basic BookStore Website up to 0e0b9f542f7a2d90a8d7f8c83caca69294e234e4. This issue affects some unknown processing of the file …

Oct 11, 2025
CVE-2025-11518
5.3 MEDIUM

The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via …

Oct 11, 2025
CVE-2025-11254
4.3 MEDIUM

The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in all versions up to, …

Oct 11, 2025
CVE-2025-11167
4.7 MEDIUM

The CM Registration – Tailored tool for seamless login and invitation-based registrations plugin for WordPress is vulnerable to Open Redirect in all versions up to, …

Oct 11, 2025
CVE-2025-9496
6.4 MEDIUM

The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file_modified shortcode in all versions up to, and including, …

Oct 11, 2025
CVE-2025-9196
5.3 MEDIUM

The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to Sensitive Information Exposure in …

Oct 11, 2025
CVE-2025-11197
6.4 MEDIUM

The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'drafts' shortcode in all versions up to, and including, 2.6.1 …

Oct 11, 2025
CVE-2025-10185
4.9 MEDIUM

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in the action nf_load_form_entries in …

Oct 11, 2025
CVE-2025-10048
4.9 MEDIUM

The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up to, and including, 3.6.31 due …

Oct 11, 2025
CVE-2025-11593
6.3 MEDIUM

A flaw has been found in CodeAstro Gym Management System 1.0. This vulnerability affects unknown code of the file /admin/actions/delete-equipment.php. This manipulation of the argument …

Oct 11, 2025
CVE-2025-11592
6.3 MEDIUM

A vulnerability was detected in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/edit-equipmentform.php. The manipulation of the argument ID …

Oct 11, 2025
CVE-2025-11591
6.3 MEDIUM

A security vulnerability has been detected in CodeAstro Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/actions/delete-member.php. The …

Oct 11, 2025
CVE-2025-58285
5.3 MEDIUM

Permission control vulnerability in the media module. Successful exploitation of this vulnerability may affect service confidentiality.

Oct 11, 2025
CVE-2025-58284
5.9 MEDIUM

Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service confidentiality.

Oct 11, 2025
CVE-2025-58283
5.5 MEDIUM

Permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service confidentiality.

Oct 11, 2025
CVE-2025-58278
6.2 MEDIUM

Identity authentication bypass vulnerability in the Gallery app. Successful exploitation of this vulnerability may affect service confidentiality.

Oct 11, 2025
CVE-2025-58277
4.0 MEDIUM

Permission verification bypass vulnerability in the Camera app. Successful exploitation of this vulnerability may affect service confidentiality.

Oct 11, 2025
CVE-2025-9560
6.4 MEDIUM

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_newsletter shortcode in all versions up to, and including, …

Oct 11, 2025
CVE-2025-11380
5.9 MEDIUM

The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a …

Oct 11, 2025
CVE-2025-54654
6.2 MEDIUM

Permission control vulnerability in the Gallery module. Successful exploitation of this vulnerability may affect service confidentiality

Oct 11, 2025
CVE-2025-11590
6.3 MEDIUM

A weakness has been identified in CodeAstro Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/equipment-entry.php. Executing a …

Oct 11, 2025
CVE-2025-9554
5.3 MEDIUM

Vulnerability in Drupal Owl Carousel 2.This issue affects Owl Carousel 2: *.*.

Oct 10, 2025
CVE-2025-9553
5.3 MEDIUM

Vulnerability in Drupal API Key manager.This issue affects API Key manager: *.*.

Oct 10, 2025
CVE-2025-9552
5.3 MEDIUM

Vulnerability in Drupal Synchronize composer.Json With Contrib Modules.This issue affects Synchronize composer.Json With Contrib Modules: *.*.

Oct 10, 2025
CVE-2025-9551
6.5 MEDIUM

Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Protected Pages allows Brute Force.This issue affects Protected Pages: from 0.0.0 before 1.8.0, from 7.X-1.0 before …

Oct 10, 2025
CVE-2025-9550
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Facets allows Cross-Site Scripting (XSS).This issue affects Facets: from 0.0.0 before 2.0.10, …

Oct 10, 2025
CVE-2025-9549
6.5 MEDIUM

Missing Authorization vulnerability in Drupal Facets allows Forceful Browsing.This issue affects Facets: from 0.0.0 before 2.0.10, from 3.0.0 before 3.0.1.

Oct 10, 2025
CVE-2025-52647
6.1 MEDIUM

The BigFix WebUI application responds with HOST information from the HTTP header field making it vulnerable to Host Header Poisoning Attacks.

Oct 10, 2025
CVE-2025-11626
5.5 MEDIUM

MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service

Oct 10, 2025
CVE-2025-61912
5.3 MEDIUM

python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, ldap.dn.escape_dn_chars() escapes \x00 incorrectly by emitting a backslash …

Oct 10, 2025
CVE-2025-61911
6.5 MEDIUM

python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, the sanitization method `ldap.filter.escape_filter_chars` can be tricked to …

Oct 10, 2025
CVE-2025-11589
6.3 MEDIUM

A security flaw has been discovered in CodeAstro Gym Management System 1.0. Affected is an unknown function of the file /admin/user-payment.php. Performing a manipulation of …

Oct 10, 2025
CVE-2025-11588
6.3 MEDIUM

A vulnerability was identified in CodeAstro Gym Management System 1.0. This impacts an unknown function of the file /customer/index.php. Such manipulation of the argument fullname …

Oct 10, 2025
CVE-2025-62245
4.3 MEDIUM

Cross-site request forgery (CSRF) vulnerability in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update …

Oct 10, 2025
CVE-2025-62158
5.3 MEDIUM

Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system did stored the attachments uploaded by …

Oct 10, 2025
CVE-2025-61925
6.5 MEDIUM

Astro is a web framework. Prior to version 5.14.2, Astro reflects the value in `X-Forwarded-Host` in output when using `Astro.url` without any validation. It is …

Oct 10, 2025
CVE-2025-61505
6.5 MEDIUM

e107 CMS thru 2.3.3 are vulnerable to insecure deserialization in the `install.php` script. The script processes user-controlled input in the `previous_steps` POST parameter using `unserialize(base64_decode())` …

Oct 10, 2025
CVE-2025-11581
5.3 MEDIUM

A security vulnerability has been detected in PowerJob up to 5.1.2. This vulnerability affects unknown code of the file /openApi/runJob of the component OpenAPIController. Such …

Oct 10, 2025
CVE-2025-60838
6.5 MEDIUM

An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file.

Oct 10, 2025
CVE-2025-60268
6.5 MEDIUM

An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/cgUploadController.do. An …

Oct 10, 2025
CVE-2025-11618
4.3 MEDIUM

A missing validation check in FreeRTOS-Plus-TCP's UDP/IPv6 packet processing code can lead to an invalid pointer dereference when receiving a UDP/IPv6 packet with an incorrect …

Oct 10, 2025
CVE-2025-11617
5.4 MEDIUM

A missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing code can lead to an out-of-bounds read when receiving a IPv6 packet with incorrect payload lengths …

Oct 10, 2025
CVE-2025-11616
5.4 MEDIUM

A missing validation check in FreeRTOS-Plus-TCP's ICMPv6 packet processing code can lead to an out-of-bounds read when receiving ICMPv6 packets of certain message types which …

Oct 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.